]> source.dussan.org Git - nextcloud-server.git/commitdiff
prevent XSS
authorFrank Karlitschek <frank@owncloud.org>
Sun, 10 Jun 2012 17:52:23 +0000 (19:52 +0200)
committerFrank Karlitschek <frank@owncloud.org>
Sun, 10 Jun 2012 17:52:23 +0000 (19:52 +0200)
apps/external/ajax/setsites.php

index c758a3508c5cdce7063240ed29c38bef0efd12c4..772863974ae4bcf708a5f04961abbf88a74974bc 100644 (file)
@@ -12,7 +12,7 @@ OCP\User::checkAdminUser();
 $sites = array();
 for ($i = 0; $i < sizeof($_POST['site_name']); $i++) {
        if (!empty($_POST['site_name'][$i]) && !empty($_POST['site_url'][$i])) {
-               array_push($sites, array($_POST['site_name'][$i], $_POST['site_url'][$i]));
+               array_push($sites, array(strip_tags($_POST['site_name'][$i]), strip_tags($_POST['site_url'][$i])));
        }
 }